Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
168 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.78% | — | Oracle Banking Corporate Lending | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 12.3.0-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking… | |
| Modificada | Alta (7.5) | 3.9% | — | Apache KafkaOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Liquidity Management+9 | 14/1/2020 | 17/6/2026 | When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can… | |
| Modificada | Alta (7.5) | 1.4% | — | Univention Corporate Server | 17/7/2019 | 17/6/2026 | Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure. The impact is: Loss of Confidentiality. The component is: function data_on_connection() in src/callback.c. The attack vector is: network connectivity. The fixed version is: 12.0.1-4… | |
| Modificada | Media (5.4) | 8.9% | 💥 Exploit | Pivotal Software Spring Security OauthOracle Banking Corporate Lending | 12/6/2019 | 17/6/2026 | Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization endpoint… | |
| Modificada | Crítica (9.8) | 9.5% | — | Apache PdfboxApache JamesFedoraproject FedoraOracle Banking Corporate Lending Process Management+10 | 17/4/2019 | 17/6/2026 | Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF. | |
| Modificada | Media (6.5) | 17% | 💥 Exploit | Pivotal Software Spring Security OauthOracle Banking Corporate Lending | 7/3/2019 | 17/6/2026 | Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization… | |
| Modificada | Alta (8.1) | 2.0% | — | Oracle Banking Corporate Lending | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (5.4) | 1.2% | — | Oracle Banking Corporate Lending | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (5.3) | 1.6% | — | Oracle Banking Corporate Lending | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0, 14.0.0 and 14.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (5.4) | 1.2% | — | Oracle Banking Corporate Lending | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (5.4) | 1.6% | — | Oracle Banking Corporate Lending | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (6.5) | 2.2% | — | Oracle Banking Corporate Lending | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (5.3) | 2.0% | — | Oracle Banking Corporate Lending | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (6.3) | 1.4% | — | Oracle Banking Corporate Lending | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Banking Corporate Lending | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (5.4) | 1.0% | — | Oracle Banking Corporate LendingOracle Banking PaymentsOracle Flexcube Enterprise Limits AND Collateral ManagementOracle Flexcube Investor Servicing+1 | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Banking Corporate LendingOracle Banking PaymentsOracle Flexcube Enterprise Limits AND Collateral ManagementOracle Flexcube Investor Servicing+1 | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Modificada | Media (6.5) | 1.9% | — | Oracle Banking Corporate LendingOracle Banking PaymentsOracle Flexcube Enterprise Limits AND Collateral ManagementOracle Flexcube Investor Servicing+1 | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Alta (7.1) | 1.6% | — | Oracle Banking Corporate LendingOracle Banking PaymentsOracle Flexcube Enterprise Limits AND Collateral ManagementOracle Flexcube Investor Servicing+1 | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (5.3) | 1.1% | — | Oracle Banking Corporate Lending | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0 and 12.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking… | |
| Modificada | Alta (8.1) | 1.6% | — | Oracle Banking Corporate Lending | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking… | |
| Modificada | Alta (8.8) | 1.7% | — | Oracle Banking Corporate Lending | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking… | |
| Modificada | Media (4.3) | 2.1% | — | IBM Social Media AnalyticsIBM Financial Transaction ManagerIBM Financial Transaction Manager FOR Check ServicesIBM Financial Transaction Manager FOR Corporate Payment Services | 28/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media Analytics 1.3 before… | |
| Modificada | Media (5.4) | 0.27% | — | Magzter Youth Incorporated | 19/10/2014 | 17/6/2026 | The Youth Incorporated (aka com.magzter.youthincorporated) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Princetoncorporatesolutions Taking Your Company Public | 19/10/2014 | 17/6/2026 | The Taking Your Company Public (aka biz.app4mobile.app_016e43d03ee54d1facd6c9532a00e724.app) application 1.28.44.441 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |